CSA STAR Registry — Level 1 (Self-Assessment) سجل CSA STAR — المستوى الأول (تقييم ذاتي)

Everything internal audit does,
in one platform.

كل ما تقوم به المراجعة الداخلية،
في منصة واحدة.

Explore how AuditFlow runs the full engagement lifecycle — plan, execute, report, follow up — with AI that drafts and auditors who decide. Click through the sections below.

استكشف كيف يدير AuditFlow دورة المراجعة كاملة — تخطيط، وتنفيذ، وتقرير، ومتابعة — بذكاء اصطناعي يصيغ ومراجعين يقرّرون. تنقّل بين الأقسام أدناه.

10Core modulesوحدة أساسية
7AI drafting toolsأدوات صياغة بالذكاء الاصطناعي
2Languages, fullyلغتان بالكامل
0Licences for auditeesتراخيص للجهات الخاضعة
The lifecycle دورة المراجعة

Click a phase to see what happens

اضغط على أي مرحلة لترى ما يحدث فيها

Each phase feeds the next. Nothing is re-keyed between spreadsheets, email and shared drives.

كل مرحلة تُغذّي التي تليها، دون إعادة إدخال البيانات بين الملفات والبريد والمجلدات المشتركة.

01
Plan
التخطيط
Universe & annual planكون المراجعة والخطة السنوية
02
Execute
التنفيذ
Fieldwork & evidenceالعمل الميداني والأدلة
03
Report
التقرير
Findings & distributionالملاحظات والتوزيع
04
Follow up
المتابعة
Remediation to closureالمعالجة حتى الإغلاق

Build a risk-based annual plan you can defend

ابنِ خطة سنوية قائمة على المخاطر يمكنك الدفاع عنها

Audit universeكون المراجعة

Register every auditable entity — company, department, process — with owners and attributes.

سجّل كل وحدة قابلة للمراجعة — شركة، أو إدارة، أو عملية — مع الملاك والخصائص.

Risk assessmentتقييم المخاطر

Score inherent and residual risk against a reusable control library.

قيّم المخاطر المتأصلة والمتبقية مقابل مكتبة ضوابط قابلة لإعادة الاستخدام.

AI plan proposalاقتراح الخطة بالذكاء الاصطناعي

Generate a candidate annual plan from your department and process data — then edit it.

وَلِّد خطة سنوية مقترحة من بيانات الإدارات والعمليات — ثم عدّلها.

Plan generates engagementsالخطة تُنشئ العمليات

Approved plan items become real audits with scope, team and dates.

بنود الخطة المعتمدة تتحول إلى عمليات مراجعة فعلية بنطاق وفريق وتواريخ.

Run fieldwork without chasing evidence by email

نفّذ العمل الميداني دون مطاردة الأدلة بالبريد

Work programsبرامج العمل

Procedures per risk, assigned to team members, with execution status.

إجراءات لكل خطر، مسندة لأعضاء الفريق، مع حالة التنفيذ.

Work papersأوراق العمل

Templated documentation with preparer and reviewer sign-off.

توثيق بقوالب جاهزة باعتماد المُعِد والمراجع.

Auditee portalبوابة الجهة الخاضعة

Send a secure link; they upload evidence with no account and no licence.

أرسل رابطًا آمنًا؛ يرفعون الأدلة دون حساب ودون ترخيص.

Sampling & data analyticsالعينات وتحليل البيانات

Draw samples and analyse imported data with assisted column mapping.

اسحب العينات وحلّل البيانات المستوردة مع ربط أعمدة مُساعَد.

From finding to signed-off report

من الملاحظة إلى تقرير معتمد

Finding workflowدورة الملاحظة

Draft, multi-level review, send to auditee, capture management response.

مسودة، ومراجعة متعددة المستويات، وإرسال للجهة الخاضعة، وتوثيق رد الإدارة.

AI draftingالصياغة بالذكاء الاصطناعي

Turn rough notes into condition, impact, root cause and recommendation.

حوّل الملاحظات الأولية إلى حالة وأثر وسبب جذري وتوصية.

Executive summaryالملخص التنفيذي

Generated from the engagement's own findings, then edited by the lead auditor.

يُولَّد من ملاحظات العملية نفسها، ثم يعدّله المراجع المسؤول.

Controlled distributionتوزيع مُحكم

Send to the right stakeholders and log who received what, and when.

أرسل لأصحاب العلاقة وسجّل من استلم ماذا ومتى.

Prove that findings actually got fixed

أثبت أن الملاحظات عولجت فعليًا

Recommendation trackingمتابعة التوصيات

Owner, due date, status and evidence of closure for every recommendation.

مالك، وتاريخ استحقاق، وحالة، ودليل إغلاق لكل توصية.

Aggregated follow-upالمتابعة المجمّعة

One portfolio view across all engagements for the audit committee.

عرض واحد على مستوى المحفظة لكل العمليات للجنة المراجعة.

Monitoring rulesقواعد المراقبة

Continuous control monitoring that flags exceptions between engagements.

مراقبة مستمرة للضوابط ترصد الاستثناءات بين العمليات.

Trends & analyticsالاتجاهات والتحليلات

See recurring themes and ageing across periods, not just one audit.

اعرف الأنماط المتكررة والتقادم عبر الفترات، لا عملية واحدة فقط.

Module explorer مستكشف الوحدات

Filter the platform by what you need

تصفّح المنصة حسب ما تحتاجه

Audit Universe
كون المراجعة

Every auditable entity with owners, attributes and risk scoring.

كل وحدة قابلة للمراجعة مع الملاك والخصائص وتقييم المخاطر.

Annual Plans
الخطط السنوية

Risk-based plan that generates the year's engagements, with AI proposal.

خطة قائمة على المخاطر تُنشئ عمليات العام، مع اقتراح بالذكاء الاصطناعي.

Audits & Work Programs
عمليات المراجعة وبرامج العمل

Scope, team assignment, procedures and live execution status.

النطاق، وإسناد الفريق، والإجراءات، وحالة التنفيذ اللحظية.

Work Papers
أوراق العمل

Structured documentation, reusable templates, preparer/reviewer sign-off.

توثيق منظّم، وقوالب قابلة لإعادة الاستخدام، واعتماد المُعِد والمراجع.

Requirements & Auditee Portal
الطلبات وبوابة الجهة الخاضعة

Templated request lists sent as a secure link — no auditee account needed.

قوائم طلبات بقوالب تُرسل كرابط آمن — دون حساب للجهة الخاضعة.

Risk Register
سجل المخاطر

Inherent and residual assessment mapped to controls.

تقييم متأصل ومتبقٍ مرتبط بالضوابط.

Control Library
مكتبة الضوابط

Reusable controls referenced across risks, audits and monitoring rules.

ضوابط قابلة لإعادة الاستخدام عبر المخاطر والعمليات وقواعد المراقبة.

Monitoring Rules
قواعد المراقبة

Continuous control monitoring that flags exceptions between engagements.

مراقبة مستمرة للضوابط ترصد الاستثناءات بين العمليات.

Findings
الملاحظات

Full lifecycle with multi-level review and auditee response.

دورة حياة كاملة بمراجعة متعددة المستويات ورد الجهة الخاضعة.

Recommendations & Follow-up
التوصيات والمتابعة

Owner, due date and evidence of closure, with aggregated reporting.

مالك، وتاريخ استحقاق، ودليل إغلاق، مع تقارير مجمّعة.

Analytics & Trends
التحليلات والاتجاهات

Recurring themes, ageing and coverage across periods.

الأنماط المتكررة والتقادم والتغطية عبر الفترات.

Users, Roles & Permissions
المستخدمون والأدوار والصلاحيات

Granular role-based access enforced on every screen and query.

صلاحيات دقيقة قائمة على الأدوار مُطبَّقة على كل شاشة واستعلام.

Activity & Sign-in Log
سجل النشاط وتسجيل الدخول

Tamper-evident hash-chained log plus sign-in monitoring with alerts.

سجل تسلسلي مُجزّأ مقاوم للتلاعب مع مراقبة الدخول والتنبيهات.

Companies, Departments & Processes
الشركات والأقسام والعمليات

The organisational backbone every other module references.

العمود التنظيمي الذي تشير إليه كل الوحدات الأخرى.

Data Analytics
تحليل البيانات

Import datasets with assisted column mapping and run analysis routines.

استورد البيانات بربط أعمدة مُساعَد ونفّذ إجراءات التحليل.

AI, demonstrated الذكاء الاصطناعي بمثال

The AI drafts. Your auditors decide.

الذكاء الاصطناعي يصيغ، ومراجعوك يقرّرون.

Pick a task to see what the auditor puts in, and what comes back as an editable draft.

اختر مهمة لترى ما يُدخله المراجع، وما يعود كمسودة قابلة للتعديل.

Auditor inputمُدخل المراجع

"3 of 25 purchase orders sampled had no evidence of approval before the PO was issued. Two were above the 50k threshold."

«٣ من ٢٥ أمر شراء في العينة بدون دليل اعتماد قبل الإصدار. اثنان منها تجاوزا حد الـ ٥٠ ألف.»

Department: Procurement · Industry: Manufacturing · Description: centralised purchasing, 3-way match, 40 active suppliers.

الإدارة: المشتريات · النشاط: التصنيع · الوصف: شراء مركزي، ومطابقة ثلاثية، و٤٠ مورّدًا نشطًا.

Upload: Procurement Policy v4.pdf (18 pages) — the auditor uploads the document as-is.

رفع: سياسة المشتريات الإصدار ٤.pdf (١٨ صفحة) — يرفع المراجع الوثيقة كما هي.

Editable draft returnedمسودة قابلة للتعديل

Condition: 12% of sampled POs lacked pre-issuance approval.
Impact: Unauthorised commitment of funds; two instances exceeded the delegated authority threshold.
Root cause: The system permits PO issuance before the approval workflow completes.
Recommendation: Enforce a system block on PO issuance until approval is recorded.

الحالة: ١٢٪ من أوامر الشراء في العينة بلا اعتماد مسبق.
الأثر: ارتباط مالي غير مُصرّح به؛ وحالتان تجاوزتا حد الصلاحية المفوّضة.
السبب الجذري: النظام يسمح بإصدار أمر الشراء قبل اكتمال دورة الاعتماد.
التوصية: فرض حظر آلي على الإصدار حتى تسجيل الاعتماد.

A ranked list of candidate risks — split purchases to bypass thresholds, supplier master-data manipulation, duplicate payments, PO/GRN mismatch — each with a suggested category and rationale, ready to accept, edit, or discard.

قائمة مخاطر مرشّحة مرتبة — تجزئة المشتريات لتجاوز الحدود، والتلاعب ببيانات الموردين، والمدفوعات المكررة، وعدم تطابق أمر الشراء مع الاستلام — لكلٍّ تصنيف مقترح ومبرر، جاهزة للقبول أو التعديل أو الحذف.

Four structured outputs: the processes the policy describes, the risks it implies, the controls it states, the gaps against the framework — plus the evidence requests to send the auditee.

أربعة مخرجات منظّمة: العمليات التي تصفها السياسة، والمخاطر التي تنطوي عليها، والضوابط التي تنص عليها، والفجوات مقابل الإطار — إضافة إلى طلبات الأدلة لإرسالها للجهة الخاضعة.

Every AI output is a draft for human review — never an automated decision. All AI features work in Arabic and English. كل مخرجات الذكاء الاصطناعي مسودة للمراجعة البشرية — وليست قرارًا آليًا. وجميع الخصائص تعمل بالعربية والإنجليزية.
Auditee portal بوابة الجهة الخاضعة

Evidence collection without licences or logins

جمع الأدلة دون تراخيص أو حسابات

The single biggest time sink in most audits is chasing documents. AuditFlow moves that exchange out of email and into a tracked, secure workspace the auditee can use without any onboarding.

أكبر مُستنزِف للوقت في معظم عمليات المراجعة هو مطاردة المستندات. ينقل AuditFlow هذا التبادل من البريد إلى مساحة آمنة ومتتبَّعة يستخدمها الطرف الآخر دون أي تهيئة.

1
Build the request list from a templateابنِ قائمة الطلبات من قالب

Reusable requirement templates mean you are not retyping the same 30 requests every audit.

قوالب الطلبات القابلة لإعادة الاستخدام تعني ألا تعيد كتابة نفس الثلاثين طلبًا كل مرة.

2
Send one secure, expiring linkأرسل رابطًا آمنًا واحدًا محدد الصلاحية

No account creation, no password, no licence for the auditee.

دون إنشاء حساب، أو كلمة مرور، أو ترخيص للجهة الخاضعة.

3
They respond item by itemيستجيبون بندًا ببند

Upload evidence, mark provided / not applicable / will provide later, and ask questions inline.

رفع الأدلة، وتحديد: تم التقديم / غير منطبق / سيُقدَّم لاحقًا، وطرح الاستفسارات مباشرة.

4
Everything lands in the engagementكل شيء يُسجَّل داخل العملية

Every upload, status change and message is recorded against the audit with a full trail.

كل مرفق وتغيير حالة ورسالة يُسجَّل ضمن المراجعة بمسار تدقيق كامل.

Comparison مقارنة

Spreadsheets, generic GRC, or AuditFlow

ملفات Excel، أو نظام GRC عام، أو AuditFlow

Capabilityالقدرة Spreadsheets + emailExcel والبريد Generic GRC suiteنظام GRC عام AuditFlowAuditFlow
Audit-specific objects (universe, work paper, finding)كائنات خاصة بالمراجعة (كون، ورقة عمل، ملاحظة) Partlyجزئيًا
Auditee evidence collection without licencesجمع الأدلة دون تراخيص Email onlyبالبريد فقط
AI drafting of findings and plansصياغة الملاحظات والخطط بالذكاء الاصطناعي Add-onإضافة منفصلة
Full Arabic interface and Arabic AI outputواجهة عربية كاملة ومخرجات ذكاء اصطناعي بالعربية Manualيدويًا
Tamper-evident audit trail of privileged actionsمسار تدقيق مقاوم للتلاعب للإجراءات الحساسة
Review and sign-off workflow built inدورة مراجعة واعتماد مدمجة
Deployment timeزمن التشغيل Immediateفوري Monthsشهور Daysأيام
Estimate تقدير

How much time goes to admin work?

كم من الوقت يذهب للأعمال الإدارية؟

Move the sliders to see the scale of the documentation and evidence-chasing effort in your own department.

حرّك المؤشرات لترى حجم الجهد المبذول في التوثيق ومطاردة الأدلة في إدارتك.

Admin hours per yearساعات إدارية سنويًا
720

Equivalent working weeksما يعادل أسابيع عمل
18

Based on your inputs and a 40-hour week. This is the effort AuditFlow's templates, portal and AI drafting are designed to reduce — the actual reduction depends on your process. بناءً على مدخلاتك وأسبوع عمل ٤٠ ساعة. هذا هو الجهد الذي صُمّمت قوالب AuditFlow وبوابته وصياغته الذكية لتقليله — ويعتمد التقليل الفعلي على إجراءاتك.

Security & compliance الأمن والامتثال

Audit data deserves audit-grade controls

بيانات المراجعة تستحق ضوابط بمستوى المراجعة

We are listed in the Cloud Security Alliance STAR Registry at Level 1 (Self-Assessment). Our answers to the full CAIQ control questionnaire are public, so you can review our security posture before you talk to us. SOC 2 readiness is on our published roadmap. نحن مُدرجون في سجل STAR التابع لتحالف أمن السحابة عند المستوى الأول (تقييم ذاتي). وإجاباتنا على استبيان الضوابط الكامل (CAIQ) منشورة، فيمكنك مراجعة وضعنا الأمني قبل التواصل معنا. والاستعداد لشهادة SOC 2 مُدرَج في خارطة طريقنا المنشورة.

Two-factor authentication via an authenticator app is mandatory for every account. Access is role-based with granular permissions enforced on every screen and query, and an optional IP allow-list can restrict where your users may sign in from. المصادقة الثنائية عبر تطبيق مصادقة إلزامية لكل حساب. والوصول قائم على الأدوار بصلاحيات دقيقة مُطبَّقة على كل شاشة واستعلام، مع إمكانية تقييد عناوين IP التي يدخل منها مستخدموك.

Every query is scoped to your organisation at the database layer — not merely hidden in the interface. Data is encrypted with TLS 1.2+ in transit and AES-256 at rest. كل استعلام مقيَّد بمؤسستك على مستوى قاعدة البيانات — لا مجرد إخفاء في الواجهة. والبيانات مشفّرة بـ TLS 1.2+ أثناء النقل وAES-256 أثناء التخزين.

Privileged actions are written to an append-only, hash-chained log that makes tampering detectable. Sign-in attempts are logged in full, with automated alerting when credential-stuffing patterns are detected. تُكتب الإجراءات الحساسة في سجل للإضافة فقط، تسلسلي مُجزّأ، يجعل أي تلاعب قابلًا للاكتشاف. وتُسجَّل محاولات الدخول بالكامل، مع تنبيهات آلية عند رصد أنماط هجمات بيانات الاعتماد.

Daily encrypted backups with a 24-hour recovery point objective and a 2-hour recovery time objective, tested by restore drills. Our data processing agreement is mapped to GDPR, KSA PDPL, Egypt PDPL and UAE PDPL, and self-service export and anonymisation tooling is built in. نسخ احتياطية يومية مشفّرة بهدف نقطة استعادة ٢٤ ساعة وزمن استعادة ساعتان، مُختبَرة بتمارين استرجاع. واتفاقية معالجة البيانات لدينا مرتبطة بـ GDPR وأنظمة حماية البيانات في السعودية ومصر والإمارات، مع أدوات مدمجة للتصدير الذاتي وإخفاء الهوية.
Common questions أسئلة شائعة

No. Auditees respond through a secure link with no account and no licence, so your audit coverage is never limited by seat count. لا. تستجيب الجهات الخاضعة عبر رابط آمن دون حساب ودون ترخيص، فلا يكون نطاق تغطيتك محكومًا بعدد المقاعد.

The full interface runs in Arabic, and the AI drafting produces Arabic output — findings, risks, executive summaries — not just translated labels. الواجهة الكاملة تعمل بالعربية، وصياغة الذكاء الاصطناعي تُنتج مخرجات عربية — ملاحظات ومخاطر وملخصات تنفيذية — لا مجرد تسميات مترجمة.

No. Every AI output is an editable draft presented to an auditor. Nothing is issued, approved or closed automatically — professional judgement stays with your team. لا. كل مخرج مسودة قابلة للتعديل تُعرض على المراجع. ولا يُصدر أو يُعتمد أو يُغلق شيء تلقائيًا — الحكم المهني يبقى لدى فريقك.

Only the users you create, with the permissions you assign. Every database query is scoped to your organisation, and our obligations as a processor are set out in a data processing agreement you can have reviewed before signing. فقط المستخدمون الذين تنشئهم، بالصلاحيات التي تمنحها. وكل استعلام مقيَّد بمؤسستك، والتزاماتنا كمعالج للبيانات موضحة في اتفاقية معالجة يمكنك مراجعتها قبل التوقيع.

AuditFlow is delivered as a hosted service, so there is no infrastructure to procure. A working environment for your team can typically be prepared in days, not months. يُقدَّم AuditFlow كخدمة مستضافة، فلا توجد بنية تحتية للشراء. ويمكن عادةً تجهيز بيئة عمل لفريقك خلال أيام، لا شهور.

Yes. Exports use standard formats (CSV/XLSX/JSON) with original files preserved, and a full export on termination is a contractual commitment, not a favour. نعم. التصدير بصيغ قياسية (CSV/XLSX/JSON) مع الحفاظ على الملفات الأصلية، والتصدير الكامل عند إنهاء التعاقد التزام تعاقدي وليس تفضّلًا.

See it against your own audit plan

جرّبه على خطة المراجعة الخاصة بك

The fastest way to evaluate AuditFlow is a walkthrough using one of your real engagements. We will prepare a working environment for your team.

أسرع طريقة لتقييم AuditFlow هي جولة عملية على إحدى عملياتك الفعلية. وسنجهّز بيئة عمل لفريقك.